VYPR
Medium severity4.3NVD Advisory· Published Dec 9, 2025· Updated Apr 23, 2026

CVE-2025-62762

CVE-2025-62762

Description

Cross-Site Request Forgery (CSRF) vulnerability in photoboxone SMTP Mail smtp-mail allows Cross Site Request Forgery.This issue affects SMTP Mail: from n/a through <= 1.3.51.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF vulnerability in WordPress SMTP Mail plugin up to v1.3.51 allows attackers to force privileged users to execute unwanted actions.

Vulnerability

Overview

The SMTP Mail plugin for WordPress (versions through 1.3.51) contains a Cross-Site Request Forgery (CSRF) vulnerability. This flaw arises because the plugin does not properly validate or enforce anti-CSRF tokens on sensitive actions, allowing attackers to trick authenticated administrators into unknowingly performing unintended requests [1].

Exploitation

Conditions

Exploitation requires a privileged user (e.g., administrator) to interact with a crafted link or form while logged into the WordPress admin area. The attacker does not need any direct access to the site; social engineering (e.g., via email or a malicious page) is sufficient to trigger the request. The CSRF can be carried out without any special permissions beyond the victim's existing session [1].

Impact

A successful CSRF attack could enable an attacker to modify plugin settings, change email configurations, or perform other administrative actions under the victim's privileges. This could lead to email service disruption, data leakage, or further compromise of the WordPress installation. The vulnerability has a CVSS score of 4.3 (Medium) [1].

Mitigation

The vendor has released an update; users are advised to upgrade to version 1.3.52 or later. As an interim measure, restricting admin account privileges and educating users about phishing risks can reduce the likelihood of exploitation [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.